academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations,
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill us-sox-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/us-sox-expertContext preview
The summary Claude sees to decide when to auto-load this skill.
Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations,
name: us-sox-expert description: Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations, Development), entity-level controls, IT-dependent manual controls, deficiency evaluation, SOC 1 vendor reliance, and the SEC/PCAOB/DOJ enforcement triangle. allowed-tools: Read, Glob, Grep, Write
Deep, practitioner-level expertise in the Sarbanes-Oxley Act of 2002 — the U.S. federal statute that governs financial reporting controls for SEC-registrant public companies. This skill is written for the security and IT engineer who has been told they "own SOX" or "support SOX" and needs to understand what the audit machine around them actually does.
SOX is the U.S. response to the Enron and WorldCom accounting frauds of 2001–2002. It does **not** prescribe specific cybersecurity controls. What it does is impose three things on SEC-registrant public companies and their auditors:
1. **Personal accountability for financial disclosures** by the CEO and CFO (§302 and §906 certifications, with criminal exposure under §906). 2. **An annual management assessment of the design and operating effectiveness of Internal Controls over Financial Reporting (ICFR)** filed in the 10-K (§404(a)). 3. **An external auditor attestation on management's ICFR assessment** for accelerated filers (§404(b), required by 15 U.S.C. § 7262(b)).
The security/IT relevance is indirect but unavoidable: virtually every modern in-scope financial process depends on IT systems, so management's §404(a) assessment must cover the IT General Controls (ITGCs) protecting those systems, and the external auditor will test those ITGCs under AS 2201 as part of the §404(b) attestation. That ITGC testing is where a security or platform engineer's day-to-day SOX work happens.
The SCF crosswalk maps only **4 SCF controls** to SOX. That is correct, not a gap — SOX's statutory text is structured around officer certifications, auditor independence, audit committee composition, document retention, and disclosure rules, not technical control objectives. The control catalog that practitioners actually test against is **COSO 2013 Internal Control — Integrated Framework** at the entity-level layer, **COBIT 5 / 2019** for IT-process controls, and the **AICPA Trust Services Criteria** where ITGC overlap exists (e.g., a SOC 1 Type II from a service organization is the typical vendor-reliance evidence).
So SOX's role in this plugin is **the governance and accountability frame**:
The actual control objectives flow from COSO + COBIT + the auditor's own internal control workpaper templates. This plugin helps you scope SOX correctly, run an honest ICFR-style gap assessment via the SCF crosswalk, and assemble the ITGC evidence package an external auditor will recognize — without pretending SOX is a security framework.
Any company whose securities are **registered under §12** of the Securities Exchange Act of 1934 (listed on a U.S. national securities exchange like NYSE or Nasdaq) **or** required to file periodic reports under **§15(d)** of the 1934 Act (e.g., issuers with publicly registered debt). In short: **U.S.-listed public companies**, plus a number of issuers required to file 10-K / 10-Q / 8-K reports with the SEC even if not exchange-listed.
A non-U.S. company with securities listed on a U.S. exchange is generally subject to SOX, with limited carve-outs and accommodation for home-country governance practices (e.g., 20-F annual filings instead of 10-K, but the §302 and §404 substance still applies). Don't assume "we're headquartered abroad" gets you out of SOX scope.
Two common cases where a private company should be running SOX-grade ICFR even though it is not yet a §12 registrant:
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.